CVE-2026-81207
8.5IBM · DataStage on Cloud Pak for Data
A Server-Side Request Forgery vulnerability in IBM DataStage on Cloud Pak for Data allows authenticated tenants to perform unauthorized outbound fetches and access internal cluster services.
Executive summary
An authenticated tenant can exploit a Server-Side Request Forgery vulnerability in IBM DataStage on Cloud Pak for Data to access sensitive internal cluster resources and co-tenant services.
Vulnerability
This vulnerability is a Server-Side Request Forgery (CWE-918) that allows any authenticated tenant, regardless of project membership or role, to control the target scheme, host, port, and path of outbound requests originating from the shared-infrastructure pod. Because the ds-canvas pod resides on the OpenShift overlay, an attacker can reach co-tenant services, internal APIs, and link-local addresses, with responses reflected back to the attacker.
Business impact
The exploitation of this vulnerability poses a severe risk to data confidentiality and internal infrastructure integrity. By leveraging the shared-infrastructure pod to query internal APIs or co-tenant services, an attacker can bypass network segmentation to exfiltrate sensitive data or perform unauthorized reconnaissance. Given the CVSS score of 8.5, this high-severity flaw requires immediate attention to prevent unauthorized access within the multi-tenant environment.
Remediation
Immediate Action: Upgrade DataStage on Cloud Pak for Data to version 5.4 patch 5 or later as directed by the vendor.
Proactive Monitoring: Review access logs for unusual outbound connection patterns originating from the ds-canvas pod and monitor for unauthorized interaction with internal cluster APIs.
Compensating Controls: Implement strict network policies within the OpenShift environment to restrict egress traffic from the ds-canvas pod to only necessary and trusted endpoints.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The ability for any authenticated user to perform arbitrary outbound requests from a high-privilege cluster pod represents a significant security breach potential. Organizations must prioritize the application of the vendor-provided patch to 5.4 patch 5 or later to eliminate this vector. Failure to remediate this vulnerability may allow attackers to pivot from a low-privilege account to a full compromise of internal cluster services.
More IBM CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section